PT-2026-81202 · Unknown · Ashauthentication

·

CVE-2026-65633

·

Published

2026-08-25

·

Updated

2026-08-27

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 3.10.5 through 4.14.1 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.12
Description Improper authentication allows purpose-limited JSON Web Tokens (JWTs) to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The helper function retrieve from bearer/3 verifies the signature of an Authorization: Bearer JWT and rejects tokens with an act claim, but fails to verify if the token's purpose claim equals user. When the resource is configured with require token presence for authentication? set to false, the validate token/3 helper returns {:ok, nil} without consulting the token resource, bypassing downstream purpose checks. Consequently, valid, non-expired JWTs issued for narrow purposes—such as the sign in token emitted by WebAuthn or the Password strategy—are accepted as general-purpose bearer credentials, granting full current user assignment. An attacker who obtains a valid sign in token can authenticate as the target subject, bypassing one-time-use and revocation semantics. This requires the application to use retrieve from bearer/3 on a reachable route and employ either WebAuthn or the Password strategy with sign in tokens enabled? set to true.
Recommendations Update ash authentication to version 4.14.2 or later. Update ash authentication to version 5.0.0-rc.13 or later. Set require token presence for authentication? to true to enforce purpose verification against the stored token record. Restrict access to routes utilizing the retrieve from bearer/3 helper function.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65633
GHSA-6VCJ-3H59-RRC3

Affected Products

Ashauthentication